We have discovered 167,020 live websites that are affected by CWE-269.
![]() | 58,234 websites |
![]() | 17,697 websites |
![]() | 10,427 websites |
![]() | 6,265 websites |
![]() | 6,076 websites |
![]() | 4,883 websites |
![]() | 4,012 websites |
![]() | 3,945 websites |
![]() | 3,838 websites |
![]() | 3,791 websites |
.com | 67,671 websites |
.org | 9,294 websites |
.de | 7,211 websites |
.com.br | 5,538 websites |
.it | 4,962 websites |
.co.uk | 4,106 websites |
.nl | 3,817 websites |
.fr | 3,716 websites |
.net | 3,481 websites |
.com.au | 3,382 websites |
Discovered | CVE | Description | Websites |
---|---|---|---|
Jun, 2025 | CVE-2025-4315 | CubeWP – All-in-One Dynamic Content Framework <= 1.1.23 - Authenticated (Subscriber+) Privilege Escalation | 494 |
May, 2025 | CVE-2025-29976 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | 3,592 |
May, 2025 | CVE-2025-3852 | WPshop 2 – E-Commerce 2.0.0 - 2.6.0 - Authenticated (Subscriber+) Privilege Escalation via Account Takeover | 22 |
May, 2025 | CVE-2025-4335 | Woocommerce Multiple Addresses <= 1.0.7.1 - Authenticated (Subscriber+) Privilege Escalation | 74 |
Apr, 2025 | CVE-2025-2238 | Vikinger <= 1.9.30 - Authenticated (Subscriber+) Privilege Escalation via 'vikinger_user_meta_update_ajax' | 34 |
Apr, 2025 | CVE-2025-3761 | My Tickets – Accessible Event Ticketing <= 2.0.16 - Authenticated (Subscriber+) Privilege Escalation | 101 |
Apr, 2025 | CVE-2025-2563 | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation | 6,188 |
Apr, 2025 | CVE-2025-2798 | Woffice <= 5.4.21 - Authentication Bypass via Registration Role | 499 |
Apr, 2025 | CVE-2025-2237 | WP RealEstate <= 1.6.26 - Authentication Bypass via 'process_register' | 216 |
Mar, 2025 | CVE-2025-29924 | XWiki uses the wrong wiki reference in AuthorizationManager | 59 |
Discovered | CVE | Description | Websites |
---|---|---|---|
Jul, 2024 | CVE-2024-37455 | WordPress Ultimate Addons for elementor plugin <= 1.36.31 - Privilege Escalation vulnerability | 26,976 |
May, 2024 | CVE-2023-41955 | WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability | 22,627 |
May, 2024 | CVE-2023-48757 | WordPress JetEngine plugin <= 3.2.4 - Privilege Escalation vulnerability | 18,986 |
Jun, 2022 | CVE-2022-1654 | Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation | 18,090 |
May, 2024 | CVE-2023-46145 | WordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability | 13,085 |
May, 2024 | CVE-2023-41954 | WordPress ProfilePress plugin <= 4.13.1 - Unauthenticated Limited Privilege Escalation vulnerability | 10,944 |
Aug, 2024 | CVE-2024-39634 | WordPress PowerPack Pro for Elementor plugin <= 2.10.14 - Contributor+ Privilege Escalation vulnerability | 9,195 |
Jul, 2023 | CVE-2023-3460 | Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation | 6,565 |
May, 2024 | CVE-2023-41665 | WordPress GiveWP plugin <= 2.33.0 - GiveWP Manager+ Privilege Escalation vulnerability | 6,441 |
Apr, 2025 | CVE-2025-2563 | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation | 6,188 |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.****.com | ![]() | *** | |
*****.com | ![]() | *** | |
***.int | ![]() | *,*** | |
**********.dk | ![]() | *,*** | |
******.gov | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
****.**.gov | ![]() | *,*** | |
***************.org | ![]() | *,*** | |
********.com | ![]() | *,*** | |
***********.***.au | ![]() | *,*** |